Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2231702
AlmaLinux
5946
Alpaquita
15522
Alpine
4594
Android
2912
Azure Linux
17378
BellSoft Hardened Containers
744
Bitnami
9303
Chainguard
1022944
CleanStart
3580
CRAN
14
crates.io
2732
Debian
68307
Docker Hardened Images
1
Echo
3105
GHC
3
GIT
105228
GitHub Actions
55
Go
9205
Hackage
32
Hex
361
Julia
1713
Linux
28817
Mageia
6224
Maven
7040
MinimOS
143890
npm
228730
NuGet
1869
opam
29
openEuler
8800
openSUSE
14458
OSS-Fuzz
4003
Packagist
7101
Pub
11
PyPI
25152
Red Hat
23316
Rocky Linux
4286
Root
19535
RubyGems
5326
SUSE
23078
SwiftURL
60
TuxCare
9578
Ubuntu
65380
VSCode
21
Wolfi
331319
ID
Packages
Summary
Published
arrow_upward
Attributes
EEF-CVE-2026-92106
Hex/lazy_html
github.com/dashbitco/lazy_html
lazy_html serializes SVG and MathML style and script text unescaped, allowing mutation XSS
16 hours ago
Fix available
Severity - 2.3 (Low)
EEF-CVE-2026-93477
Hex/ash
github.com/ash-project/ash
Private action arguments can be set by user input on the bulk destroy and bulk update paths in Ash
19 hours ago
Fix available
Severity - 5.9 (Medium)
CVE-2026-97724
github.com/software-mansion/react-native-reanimated
See record for full details
yesterday
Fix available
Severity - 5.3 (Medium)
CVE-2026-53493
github.com/containerd/containerd
Containerd has image-pull DoS via crafted OCI index graph amplification
yesterday
No fix available
Severity - 6.9 (Medium)
CVE-2026-97636
github.com/apache/airflow
Apache Airflow HashiCorp provider: HashiCorp Vault secrets backend: team-scope guard bypass via user-controlled key
yesterday
Fix available
CVE-2026-93353
github.com/9001/copyparty
copyparty SFTP Volume Restriction Bypass via mkdir/rmdir/chattr Handlers
yesterday
No fix available
Severity - 6.0 (Medium)
CVE-2026-48543
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description
yesterday
No fix available
Severity - 5.1 (Medium)
CVE-2026-48542
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field
yesterday
No fix available
Severity - 5.1 (Medium)
CVE-2026-48541
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field
yesterday
No fix available
Severity - 5.1 (Medium)
CVE-2026-48540
github.com/krayin/laravel-crm
Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title
yesterday
No fix available
Severity - 5.1 (Medium)
CVE-2026-96883
github.com/aws/pgcollection
Type confusion in AWS pgcollection allows remote code execution
yesterday
No fix available
Severity - 8.7 (High)
CVE-2026-57440
github.com/starcitizenwiki/mediawiki-extensions-embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
yesterday
Fix available
Severity - 7.5 (High)
CVE-2026-48073
github.com/docmost/docmost
Docmost: Page export can include restricted same-space attachments through forged attachmentId
yesterday
Fix available
Severity - 4.3 (Medium)
CVE-2026-52853
github.com/docmost/docmost
Docmost: Privilege Escalation - ADMIN Can Invite Users as OWNER
yesterday
Fix available
Severity - 5.2 (Medium)
CVE-2026-61823
github.com/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
yesterday
Fix available
Severity - 7.3 (High)
CVE-2026-48072
github.com/docmost/docmost
Docmost: Public image fileName path traversal leads to unauthorized local file read
yesterday
Fix available
Severity - 5.3 (Medium)
Load more...
GIT - OSV